How does password strength policy work in Plesk?

Follow

Comments

11 comments

  • Avatar
    Peter Wise

    Please consider implementing Dropbox's password strength library in future versions of plesk. https://github.com/dropbox/zxcvbn

    Right now (Plesk Onyx Version 17.8.11) very secure passwords such as applaud-bisque-batch-forefoot won't even pass the "medium" filter, and very bad passwords such as Pa$$word123 are marked "Strong".

    Brute force cracking continues to get more sophisticated and the current strength ratings are misleading.

    0
    Comment actions Permalink
  • Avatar
    Ivan Postnikov

    Hello @Peter,

    Thank you for sharing your idea. I have created a feature suggestion.

    The top-rated features will be implemented in next Plesk updates.

    0
    Comment actions Permalink
  • Avatar
    EFTHIMIOS SIDERIS (Edited )

    Plesk REST API fails to create ftp user with some ftp_password e.g. b&3$0BRldB~1 with message: "Do not use quotes, space and national alphabet characters in a password. The password length should be from 5 to 14 characters in length, and it should not contain the username."

    while there is no problem using the same password through dashboard.

    Am I doing something wrong or is a bug?

    Plesk Obsidian Web Host Edition
    Version 18.0.27

    0
    Comment actions Permalink
  • Avatar
    Renan Genova Ferreira

    Hello, EFTHIMIOS SIDERIS!

    Can you please tell the OS version you have Plesk Installed?

    Thank you

    0
    Comment actions Permalink
  • Avatar
    EFTHIMIOS SIDERIS

    Hello,

    OS is: CentOS Linux 8.1.1911

    0
    Comment actions Permalink
  • Avatar
    EFTHIMIOS SIDERIS

    Hello again,

    Nobody can answer?

    Thank you

    0
    Comment actions Permalink
  • Avatar
    Anton Maslov

    Hello,

    Unfortunately there is nothing we can suggest based on the provided information. Please create a support request to troubleshoot the issue.

    0
    Comment actions Permalink
  • Avatar
    Xanthorr (Edited )

    Could you please add the hyphen, period and comma - . , characters to the special characters scoring?

    Currently they don't affect the scoring while they are valid and good for creating safe passwords that you can also remember. Some password generators, like the one in iOS/macOS Safari, only support hyphens. So even though it does generate safe passwords they never pass the medium Plesk policy.

    0
    Comment actions Permalink
  • Avatar
    Northland SysAdmin

    I would like to make a further suggestion.  The description of password strength for strong is a little misleading as someone who puts in all the characters required with the proper length can still be considered Medium strength until some extra characters are added.  The description should be a little more accurate regarding that and I agree that the passwords with long and varied words should also pass for strong, but do not.

    Thank you

    0
    Comment actions Permalink
  • Avatar
    Ivan Postnikov

    Hello Xanthorr and Northland SysAdmin

    Thank you for the suggestions, please, don't hesitate to share your ideas here: https://plesk.uservoice.com/forums/184549-feature-suggestions

    Suggestions are monitored by RnD and popular are implemented.

    0
    Comment actions Permalink
  • Avatar
    Darko Bazulj

    I would suggest if you can add option to set length of password in  password policy.
    Difference between strong and very strong is big and length of 12 would be optimal.
    Password complexity should stay  but it would be better if we can control the length.

    0
    Comment actions Permalink

Please sign in to leave a comment.

Have more questions? Submit a request